Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
cinci zoo sniper
Mar 15, 2013




https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=852751

:eyepop:

Adbot
ADBOT LOVES YOU

cinci zoo sniper
Mar 15, 2013




https://twitter.com/gitlabstatus/status/826591961444384768

cinci zoo sniper
Mar 15, 2013




8 years of police efforts fell to ransomware

cinci zoo sniper
Mar 15, 2013




CommunistPancake posted:

the tinfoil hat part of me thinks it was erased on purpose and disguised as ransomware
a higher-up pope in russia did roadkill someone with his new shiny bmw a few years back. naturally, next thursday after the incident hacker attack did irreversibly correct all surveillance footage on police's servers

cinci zoo sniper
Mar 15, 2013




fix your country, spankmeister

cinci zoo sniper
Mar 15, 2013




i know that cms vulns are cheating, but lomarf

cinci zoo sniper
Mar 15, 2013




i use teamviewer for family computer janitoring, but only since they know how to use it

cinci zoo sniper
Mar 15, 2013




Powaqoatse posted:

i had to help my sister with a thing a week ago & used teamviewer :ohdear:

it was just an app she opened and then closed and deleted after, i dont think she even has admin rights on her macbook

did i gently caress up bigtime?
no

cinci zoo sniper
Mar 15, 2013




since i need win 10/fedora/anroid, ive settled with keepass file in a onedrive folder

cinci zoo sniper
Mar 15, 2013




i have 40 something accounts on keepass, and some of the more useful keys to avoid losing. couldve been noticeably more, but im slow to visit random old poo poo so i add new accounts and change info on the old ones as they come and go

cinci zoo sniper
Mar 15, 2013




http://www.redmondpie.com/firm-that-helped-fbi-break-into-san-bernardino-iphone-gets-hacked-tools-leaked-online/ #whoa

cinci zoo sniper
Mar 15, 2013




ate all the Oreos posted:

do they even care about games getting cracked? i thought all games were cracked within a week of like the press copies leaving the publisher's office and everyone just accepted that, do game companies still do that thing where they drum up a bunch of press on how THIS ONE'S UNCRACKABLE BOYS and then act surprised when it's cracked in under a week?
they don't do that press poo poo, and long since have made observable reaction to game crack. however, denuvo has been fairly good until now. much like the better anti-piracy systems of the past

cinci zoo sniper
Mar 15, 2013




anthonypants posted:

well the biggest difference is that people want to play a new resident evil game
just cause 3 outsold resident evil 7, on pc, by an order of magnitude

cinci zoo sniper
Mar 15, 2013




ate all the Oreos posted:

RE7 has only been out for like a week and a half

also it's been cracked so that just means that piracy is an order of magnitude worse than everyone thinks!!!!!!!

oooahHhHh!!!!!

cinci zoo sniper
Mar 15, 2013




story on google vs godzilla ddos on krebs https://arstechnica.com/security/2017/02/how-google-fought-back-against-a-crippling-iot-powered-botnet-and-won/

cinci zoo sniper
Mar 15, 2013




https://www.cyberscoop.com/dark-net-markets-bug-bounty-programs/

quote:

Hansa Marketplace, a large anonymous black market which brought in an estimated $3 million in business in the last year, launched a bug bounty program this week with rewards ranging upwards of $10,000 (10 bitcoins) for people who find critical vulnerabilities.

cinci zoo sniper
Mar 15, 2013




pr0zac posted:

this is really smart for pretty much the same reason bug bounties are smart for regular companies

surprised it didn't happen sooner
just slightly amusing to see a "darknet hacker enterprise" doing something mundane

cinci zoo sniper
Mar 15, 2013




Powaqoatse posted:

ugh some dumbass kid keeps setting up game accounts with my email

im changing their passwords
:laffo:

cinci zoo sniper
Mar 15, 2013




http://www.gosugamers.net/dota2/news/43198-heavy-ddos-attacks-gets-virtus-pro-eliminated-from-dac-qualifiers (no technical details)

looks like someone did ddos aimed at knocking a russian dota 2 team out of a tournament qualifiers did grab along a district of a major city down with them

cinci zoo sniper
Mar 15, 2013




ate all the Oreos posted:

wasn't there some eve online guy who was like, a russian mobster, and had the power grid cut to a neighboring faction's leader's home town during a big fight or something
yeah. the powergrid was probably just a hosed up transformation box (say, just "corks" stolen from it), since these stories tend to grow legs real quickly. besides that, russian eve has plenty of "real business" poo poo going on - one of my former alliances did quite literally get a headhunter of sorts to track down irl and harass an alliance fleet commander who stole some assets as he left. the most yossec one was another russian alliance, called "white noise". at their peak involvement, they were not shy of ddosing enemy voip servers/jabber/other comms, or just in general trying to hack other alliances websites and poo poo, since as you might imagine - the half of it still is running on 10 year old pirate versions of various forums cms

cinci zoo sniper
Mar 15, 2013




also looks like holidayinn parent group did indeed get hacked - they had spoopy poo poo running on their credit card processing system's servers.

https://threatpost.com/intercontinental-hotels-confirms-credit-card-breach/123575/

cinci zoo sniper
Mar 15, 2013




https://arstechnica.com/tech-policy/2017/02/vizio-smart-tvs-tracked-viewers-around-the-clock-without-consent/

quote:

Vizio, one of the world's biggest makers of Smart TVs, is paying $2.2 million to settle charges it collected viewing habits from 11 million devices without the knowledge or consent of the people watching them.

According to a complaint filed Monday by the US Federal Trade Commission, Internet-connected TVs from Vizio contained ACR—short for automated content recognition—software. Without asking for permission, the ACR code captured second-by-second information about the video the TVs displayed. The software then collected other personal information and transmitted it, along with the viewing data, to servers controlled by the manufacturer. Vizio then sold the data to unnamed third-parties for purposes of audience measurement, analysis, and tracking.

cinci zoo sniper
Mar 15, 2013




Former NSA contractor may have stolen 75% of TAO’s elite hacking tools | Ars Technica https://arstechnica.com/tech-policy/2017/02/former-nsa-contractor-may-have-stolen-75-of-taos-elite-hacking-tools/

cinci zoo sniper
Mar 15, 2013




cheese-cube posted:

is there any info on how the dude exfiltrated that data? i've been going through poo poo in my head and assuming a semi-competent net-sec team with competent physical security the only way i can think of is the dude was handed a 50TB DMS DB full of all kinds of poo poo

i imagine we'll never learn this. admitting competence flaws would be opsec fuckup, admitting lack of competence would unlikely be something in interest of any federal body these days

cinci zoo sniper
Mar 15, 2013




ate all the Oreos posted:

i'm gonna guess flash drive up the butt because it's the funniest option
people used to bring the rubles in their butt out of soviet russia since there were restrictions on hard cash export over the borders of russian sfsr

cinci zoo sniper
Mar 15, 2013




cheese-cube posted:

NPAPI support : firefox :: register_globals : PHP


ah but was it 100 x 512GB flash drives on one day or one 512GB flash drive per day for 100 days?

can you even get 512GB flash drives idk

yeah, 512 gb is easy, they are like 200-300 usd each

cinci zoo sniper
Mar 15, 2013




that twitter account :eyepop:

cinci zoo sniper
Mar 15, 2013




:laffo:

cheese-cube posted:

comedy option: asked his mother to also sign the certificate

cinci zoo sniper
Mar 15, 2013




dangling pointer posted:

is there a general best practices guide for bug bounties? like how to write good, informative reports so I don't waste the reviewers time?

also a list of things you should never do like the guy on the recent risky business podcast who got banned from yahoo for exfiltrating data via a screenshot

the guides on hackerone and similar sites are pretty brief.

thanks whoever mentioned I should try bug bounties when I asked for advice earlier in the thread, I'm having fun with it
this may depend on program basis, so always check the rules on case per case basis, but some common sense things include

- log everything you did (including identifying poo poo like ip/mac/useragent/etc)
- do not interact with data that's not yours (i.e. for facebook account hack, make two dummy facebook accounts, hacker and hackee, to work the bug out)
- do not store things locally, to the best of your ability - even things like screenshots, file tree traversal logs, and so on
- do not discuss whatever you found with anyone before the reviewer

it is always better to giver reviewer more than enough data, than to leave them guessing. you do not want that

cinci zoo sniper
Mar 15, 2013




https://twitter.com/malwrhunterteam/status/828957753121112064

russians made a short writeup on this:

- 0.085 btc bail (approx 90 usd)
- uac bypass manipulates file type associations to create an elevated ransomware service

works like this:
- ipecho.net/plain and ipinfo.io/country are used to determine geoip
- tor is downloaded and used for comms with cnc server
- ransomware seeks documents with specific extensions
- encrypts contents with aes, extensions with rot-23

cinci zoo sniper
Mar 15, 2013






http://www.guru3d.com/news-story/anti-virus-vendors-are-intercepting-and-analyzing-your-https-traffic.html

cinci zoo sniper
Mar 15, 2013




apseudonym posted:

What did I just read?
eripsa, noted forums artefact

cinci zoo sniper
Mar 15, 2013




uncurable mlady posted:

trust me, you really don't want this to happen

cinci zoo sniper
Mar 15, 2013




that would've been the greatest sec fuckup

cinci zoo sniper
Mar 15, 2013




uncurable mlady posted:

i see this is your first eripsa encounter then

cinci zoo sniper
Mar 15, 2013




WrenP-Complete posted:

I agree the efforts to keep him contained (if possible).
they are like a large botnet, you can only divert them to another target

-sun tzu

cinci zoo sniper
Mar 15, 2013




LeftistMuslimObama posted:

if you look white will it really matter? im travelling to europe for a month soon and i haven't really worried about this. i was more worried about getting my passport issued (i didn't have one, never left the country) before the inauguration.
isnt social media poo poo only for foreigners, the exXxtreme vetting

cinci zoo sniper
Mar 15, 2013




reee im also pissy manedge of a child, no mods no masters reeee


now, how about we talk about vulns in computers, rather than sapience

cinci zoo sniper
Mar 15, 2013




another iot botnet, a smaller one - http://www.verizonenterprise.com/resources/reports/rp_data-breach-digest-2017-sneak-peek_xg_en.pdf

Adbot
ADBOT LOVES YOU

cinci zoo sniper
Mar 15, 2013




ate all the Oreos posted:

im updating the firmware on a point of sale system right now. the new firmware came in the form of a zip archive on some rando dropbox, and i upload it by running an anomalous bat file that, so far, has just printed an endless stream of periods to the console window

sounds like its working, op

  • Locked thread